← Back
CWE-476

5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

JSON object

Loading...

CVEs (5,434)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gnu
1Libextractor
May 13, 2026
Dec 6, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Modul...Show more
GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c.Show less
2Debian
Heimdal Project
2Debian Linux
Heimdal
May 13, 2026
Dec 6, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL...Show more
In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading to a segmentation fault. This is related to the _kdc_as_rep function in kdc/kerberos5.c and the der_length_visible_string function in lib/asn1/der_length.c.Show less
1Libav
1Libav
May 13, 2026
Dec 4, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The ff_vc1_mc_4mv_chroma4 function in libavcodec/vc1_mc.c in Libav 12.2 allows remote attackers to cause a denial of service (segmentation fault and application crash) or possibly have unspecified other impact via a craf...Show more
The ff_vc1_mc_4mv_chroma4 function in libavcodec/vc1_mc.c in Libav 12.2 allows remote attackers to cause a denial of service (segmentation fault and application crash) or possibly have unspecified other impact via a crafted file.Show less
1Libav
1Libav
May 13, 2026
Dec 4, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The vc1_decode_frame function in libavcodec/vc1dec.c in Libav 12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
1Gnu
1Binutils
May 13, 2026
Dec 4, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The coff_slurp_reloc_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (NULL pointer derefe...Show more
The coff_slurp_reloc_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted COFF based file.Show less
1Ikarussecurity
1Anti.virus
May 13, 2026
Dec 4, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
ntguard_x64.sys 0.18780.0.0 in IKARUS anti.virus 2.16.15 has a NULL pointer dereference via a 0x830000c4 DeviceIoControl request.
2Debian
Tor Project
2Debian Linux
Tor
May 13, 2026
Dec 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and applicatio...Show more
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and application crash) against directory authorities via a malformed descriptor, aka TROVE-2017-010.Show less
2Linux
Redhat
2Enterprise Linux
Linux Kernel
May 13, 2026
Nov 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).
1Tgsoft
1Vir.it Explorer
May 13, 2026
Nov 29, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a NULL value in a 0x82730020 DeviceIoControl request to \\.\Vir...Show more
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a NULL value in a 0x82730020 DeviceIoControl request to \\.\Viragtlt.Show less
1Tgsoft
1Vir.it Explorer
May 13, 2026
Nov 29, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a NULL value in a 0x82730010 DeviceIoControl request to \\.\Vir...Show more
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a NULL value in a 0x82730010 DeviceIoControl request to \\.\Viragtlt.Show less
1Tgsoft
1Vir.it Explorer
May 13, 2026
Nov 26, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a NULL value in a 0x82730008 DeviceIoControl request to \\.\Vir...Show more
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a NULL value in a 0x82730008 DeviceIoControl request to \\.\Viragtlt.Show less
1Linux
1Linux Kernel
May 13, 2026
Nov 22, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and pa...Show more
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application, as demonstrated by the keyring key type, and key addition and link creation operations.Show less
1Libming
1Libming
May 13, 2026
Nov 18, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The outputSWF_TEXT_RECORD function in util/outputscript.c in libming <= 0.4.8 is vulnerable to a NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted swf file.
1Vmware
2Fusion
Workstation
May 13, 2026
Nov 17, 2017
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal user privileges to c...Show more
VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.Show less
1Swftools
1Swftools
May 13, 2026
Nov 17, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointe...Show more
In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointer dereference) via a crafted WAV file.Show less
1Tcmu Runner Project
1Tcmu Runner
May 13, 2026
Nov 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a dbus triggered NULL pointer dereference in the tcmu-runner daemon's on_unregister_handler() function resulting in denial of service
1Libbpg Project
1Libbpg
May 13, 2026
Nov 16, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A NULL Pointer Dereference exists in VideoLAN x265, as used in libbpg 0.9.7 and other products, because the CUData::initialize function in common/cudata.cpp mishandles memory-allocation failure.
3Canonical
LinuxRedhat
3Enterprise Linux
Linux KernelUbuntu Linux
May 13, 2026
Nov 15, 2017
N/A· v4
6.3 MEDIUM· v3
6.9 MEDIUM· v2
The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-w...Show more
The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occurs after a race condition and a NULL pointer dereference.Show less
1Symantec
1Endpoint Encryption
May 13, 2026
Nov 13, 2017
N/A· v4
6.8 MEDIUM· v3
5.2 MEDIUM· v2
Prior to SEE v11.1.3MP1, Symantec Endpoint Encryption can be susceptible to a null pointer de-reference issue, which can result in a NullPointerException that can lead to a privilege escalation scenario.
1Matroska
1Mkclean
May 13, 2026
Nov 10, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Node_ValidatePtr function in corec/corec/node/node.c in mkclean 0.8.9 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.